Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks ... Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2 ...
Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks ... Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2 ...
IT Risk Compliance Specialist
Pittsburgh, PA · On-site
$95.60K/yr
... PCI-DSS). * Work closely with IT, Audit, and Operations business units to address compliance gaps. * Conduct risk assessments and recommend mitigation strategies for IT systems and processes. * Track ...
IT Risk Compliance Specialist
Pittsburgh, PA · On-site
$95.60K/yr
... PCI-DSS). * Work closely with IT, Audit, and Operations business units to address compliance gaps. * Conduct risk assessments and recommend mitigation strategies for IT systems and processes. * Track ...
Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks ... Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2 ...
Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks ... Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2 ...
Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks ... Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2 ...
Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks ... Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2 ...
... SOX, PCI-DSS) and industry standards. * Collaborate with internal audit teams and external regulators during global reviews and assessments. * Monitoring & Reporting: * Monitor IT environments ...
... SOX, PCI-DSS) and industry standards. * Collaborate with internal audit teams and external regulators during global reviews and assessments. * Monitoring & Reporting: * Monitor IT environments ...
Security GRC Manager
Plymouth Meeting, PA · On-site
$180K - $260K/yr
... PCI DSS * Establish security metrics and reporting for leadership and board-level visibility Risk Management * Lead enterprise risk assessments, including company security risk profile and third ...
Security GRC Manager
Plymouth Meeting, PA · On-site
$180K - $260K/yr
... PCI DSS * Establish security metrics and reporting for leadership and board-level visibility Risk Management * Lead enterprise risk assessments, including company security risk profile and third ...
Solution assessments Risk, Compliance & Optimization * Identify and mitigate risks: * Fraud, operational, regulatory * Ensure compliance with: * PCI DSS, data privacy, telecom regulations * Optimize:
Solution assessments Risk, Compliance & Optimization * Identify and mitigate risks: * Fraud, operational, regulatory * Ensure compliance with: * PCI DSS, data privacy, telecom regulations * Optimize:
... PCI-DSS). * Work closely with IT, Audit, and Operations business units to address compliance gaps. * Conduct risk assessments and recommend mitigation strategies for IT systems and processes. * Track ...
... PCI-DSS). * Work closely with IT, Audit, and Operations business units to address compliance gaps. * Conduct risk assessments and recommend mitigation strategies for IT systems and processes. * Track ...
IT Audit & Compliance Analyst
Oaks, PA · On-site
$96.10K - $96.60K/yr
Lead end-to-end audit readiness activities for HITRUST certification, PCI DSS assessments (SAQ or ROC), and SOC 2 Type I/II examinations. * Develop and manage structured evidence request lists across ...
IT Audit & Compliance Analyst
Oaks, PA · On-site
$96.10K - $96.60K/yr
Lead end-to-end audit readiness activities for HITRUST certification, PCI DSS assessments (SAQ or ROC), and SOC 2 Type I/II examinations. * Develop and manage structured evidence request lists across ...
... PCI DSS, SOC1/SOC2) requirements. Key Responsibilities: * Plan and conduct end-to-end UX research ... risk assessments. Qualifications : * Bachelors degree in Human-Computer Interaction (HCI ...
Quick apply
... PCI DSS, SOC1/SOC2) requirements. Key Responsibilities: * Plan and conduct end-to-end UX research ... risk assessments. Qualifications : * Bachelors degree in Human-Computer Interaction (HCI ...
... PCI DSS, SOC1/SOC2) requirements. Key Responsibilities: * Plan and conduct end-to-end UX research ... risk assessments. Qualifications : * Bachelor's degree in Human-Computer Interaction (HCI ...
... PCI DSS, SOC1/SOC2) requirements. Key Responsibilities: * Plan and conduct end-to-end UX research ... risk assessments. Qualifications : * Bachelor's degree in Human-Computer Interaction (HCI ...
senior cloud security engineer
Philadelphia, PA · On-site
$115.50K - $158.40K/yr
Provide technical insights for regulatory compliance efforts, audits, and risk assessments (e.g., GDPR, HIPAA, PCI DSS). * QualificationsBachelor's degree in Computer Science, Information Security ...
senior cloud security engineer
Philadelphia, PA · On-site
$115.50K - $158.40K/yr
Provide technical insights for regulatory compliance efforts, audits, and risk assessments (e.g., GDPR, HIPAA, PCI DSS). * QualificationsBachelor's degree in Computer Science, Information Security ...
senior cloud security engineer
Philadelphia, PA · On-site
$115.50K - $158.40K/yr
Provide technical insights for regulatory compliance efforts, audits, and risk assessments (e.g., GDPR, HIPAA, PCI DSS). Qualifications Bachelor's degree in Computer Science, Information Security, or ...
senior cloud security engineer
Philadelphia, PA · On-site
$115.50K - $158.40K/yr
Provide technical insights for regulatory compliance efforts, audits, and risk assessments (e.g., GDPR, HIPAA, PCI DSS). Qualifications Bachelor's degree in Computer Science, Information Security, or ...
senior cloud security engineer
Philadelphia, PA · On-site
$115.50K - $158.40K/yr
Provide technical insights for regulatory compliance efforts, audits, and risk assessments (e.g., GDPR, HIPAA, PCI DSS). * QualificationsBachelor's degree in Computer Science, Information Security ...
senior cloud security engineer
Philadelphia, PA · On-site
$115.50K - $158.40K/yr
Provide technical insights for regulatory compliance efforts, audits, and risk assessments (e.g., GDPR, HIPAA, PCI DSS). * QualificationsBachelor's degree in Computer Science, Information Security ...
Senior Technology Risk Auditor
Coraopolis, PA · On-site
$77.20K - $94.90K/yr
Performs risk assessments to identify relevant risks to the applicable audit and determine the ... PCI DSS, NIST, COSO), and development methodologies * Ability to perform root cause analysis and ...
Senior Technology Risk Auditor
Coraopolis, PA · On-site
$77.20K - $94.90K/yr
Performs risk assessments to identify relevant risks to the applicable audit and determine the ... PCI DSS, NIST, COSO), and development methodologies * Ability to perform root cause analysis and ...
Global Sr GRC Analyst
King Of Prussia, PA · On-site
... metrics Risk Management: • Assist with conducting gap assessments to identify threats ... Compliance: • Ensure compliance with regulatory requirements (e.g., GDPR, HIPAA, SOX, PCI-DSS ...
Global Sr GRC Analyst
King Of Prussia, PA · On-site
... metrics Risk Management: • Assist with conducting gap assessments to identify threats ... Compliance: • Ensure compliance with regulatory requirements (e.g., GDPR, HIPAA, SOX, PCI-DSS ...
Global Sr GRC Analyst
King Of Prussia, PA · On-site
... metrics Risk Management: • Assist with conducting gap assessments to identify threats ... Compliance: • Ensure compliance with regulatory requirements (e.g., GDPR, HIPAA, SOX, PCI-DSS ...
Global Sr GRC Analyst
King Of Prussia, PA · On-site
... metrics Risk Management: • Assist with conducting gap assessments to identify threats ... Compliance: • Ensure compliance with regulatory requirements (e.g., GDPR, HIPAA, SOX, PCI-DSS ...
Plan and conduct risk assessment activities according to the appropriate framework, including but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, in order to identify, assess ...
Plan and conduct risk assessment activities according to the appropriate framework, including but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, in order to identify, assess ...
Plan and conduct risk assessment activities according to the appropriate framework, including but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, in order to identify, assess ...
Plan and conduct risk assessment activities according to the appropriate framework, including but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, in order to identify, assess ...
Plan and conduct risk assessment activities according to the appropriate framework, including but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, in order to identify, assess ...
Plan and conduct risk assessment activities according to the appropriate framework, including but not limited to NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, in order to identify, assess ...
Pci Dss Risk Assessment information
What are the key skills and qualifications needed to thrive as a PCI DSS Risk Assessor, and why are they important?
What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?
What is a PCI DSS risk assessment?
What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?
| Aspect | Pci Dss Risk Assessment | Pci Dss Compliance Analyst |
|---|---|---|
| Primary Focus | Identifying and evaluating security risks related to PCI DSS requirements | Ensuring ongoing compliance with PCI DSS standards and policies |
| Responsibilities | Risk identification, vulnerability assessment, mitigation planning | Policy implementation, audit preparation, compliance documentation |
| Required Skills | Risk management, security assessment, knowledge of PCI DSS | Compliance auditing, documentation, regulatory knowledge |
| Work Environment | Security teams, risk management departments | Compliance teams, audit departments |
While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.
Other
Medical, Dental, Vision
This job post has expired today. Applications are no longer accepted.
Job description
Sr Manager, InfoSec Governance Risk and Compliance (GRC)(Pittsburgh, Pennsylvania, US)
Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.
COMPANY OVERVIEW
At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration.
We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities.
Learn more at www.ivalua.com. Follow us on LinkedIn (https://www.linkedin.com/company/ivalua) and Twitter (https://twitter.com/ivalua) .
THE OPPORTUNITY
CONTEXT:
Our InfoSec team is dedicated to building, maintaining, and continuously improving Ivalua’s Information Security program globally. We provide peace of mind and assurance of protection and safety to our customers. In this fast-growing environment, the GRC program is critical to ensuring compliance with industry standards and certifications, managing risks, and supporting business growth.
ROLE:
We are currently looking for an experienced InfoSec Governance Risk and Compliance (GRC) Sr Manager to lead a global team and own the GRC program worldwide. Reporting to the InfoSec leadership, you will manage and develop a high-performing team, drive compliance efforts, and serve as a subject matter expert on security frameworks and standards.
WHAT YOU WILL DO WITH US
-
Lead and own the Governance, Risk, and Compliance (GRC) program globally, managing and developing a high-performing team.
-
Manage and drive compliance efforts and audits for certifications such as FedRAMP, IRAP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, and others.
-
Serve as the subject matter expert (SME) on security frameworks and standards including NIST SP 800-53 Rev 5, NIST 800-171, ITAR, FedRAMP, PCI DSS, SOC2, etc., providing guidance to internal stakeholders.
-
Efficiently manage and respond to customer security audit and compliance requests in a timely manner.
-
Maintain continuous compliance and monitoring of security controls to ensure ongoing adherence to standards.
-
Collaborate closely with Sales, Marketing, and Customer Success teams to effectively communicate Ivalua’s security posture to prospects and customers.
-
Review and negotiate information security exhibits and contractual terms in partnership with the legal team.
-
Lead the Security Awareness and Training program to promote a culture of security across the organization.
-
Track, manage, and drive remediation efforts for control deficiencies and gaps identified through internal and external audits.
-
Oversee the Third Party Risk and Vendor Security Assessment program to mitigate supply chain risks.
-
Develop, maintain, and enforce InfoSec policies, standards, and plans.
YOUR PROFILE
If you have the below experience and strengths this role could be for you:
Skills and Experience:
-
At least 7+ years of proven experience leading GRC programs and managing compliance certifications and audits (FedRAMP, ISO 27001, HIPAA, SOC1/SOC2, PCI DSS, IRAP, etc.).
-
At least 3+ years experience as a direct leader, managing a team. The position will be part of an established global team with opportunity to grow the team
-
Strong knowledge of security frameworks such as NIST SP 800-53, NIST 800-171, ITAR, PCI DSS, SOC2, and FedRAMP.
-
Demonstrated ability to manage and influence stakeholders across multiple departments and time zones.
-
Excellent project management, analytical, and problem-solving skills with keen attention to detail.
-
Strong interpersonal and communication skills, capable of building trust and managing conflicts effectively.
-
Self-motivated with a high degree of initiative and ability to work independently.
-
Ability to handle multiple competing priorities and deadlines efficiently.
-
Bachelor’s degree in related field preferred or equivalent experience with proven skills
Soft Skills:
-
Excellent interpersonal, communication, and organizational skills.
-
Team player with the ability to interface effectively with a broad range of individuals and roles, including IT and vendors.
-
High degree of initiative, dependable, and able to work well with limited supervision.
WHAT HAPPENS NEXT
If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals – apply today!
Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you!
Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role.
Interviews will be conducted virtually via video or on-site with face-to-face meetings.
LIFE AT IVALUA
-
Hybrid working model (3 days in the office per week)
-
We're a team dedicated to pushing the boundaries of product innovation and technology
-
Sustainable Growth, Privately Held
-
A stable and cash-flow positive Company since 10 years
-
Snacks and weekly lunches in the office
-
Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity
-
Unlock and unleash your full professional potential with our exceptional training and career development program
-
Join a dynamic and international team of top-notch professionals who are experts in their respective fields. Collaborate with like-minded individuals who are deeply passionate and highly motivated about their work. Experience a truly diverse and inclusive work environment where your unique contributions are highly valued
-
Regular social events, competitive outings, team running events, and musical activities,
-
Comparably recognized Ivalua for the following (https://www.comparably.com/companies/ivalua) :
Powered by People - Powered by You!
United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. To help our customers make supply chains more efficient, sustainable and resilient, we rely on a global team with a variety of backgrounds, skills and views. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans. https://www.linkedin.com/company/ivalua/about/
Experience life at Ivalua - check out our captivating video (https://www.youtube.com/watch?v=irkygoq3kCc&t=4s) ! Gain insight into our unique company culture and get a glimpse of what it's like to work with us.
Ivalua’s core values include a priority on Care & Grow People. We take matters like pay equity very seriously and strive to reward our employees appropriately and fairly for their talents.
The compensation range for this position reflects the cost of labor across our US locations and is based upon careful and continual market research. In addition to location, compensation may also vary based upon job-related knowledge, skills, and experience.
Title: Manager, InfoSec Governance Risk and Compliance (GRC)
Range minimum: USD 112000
Range maximum: USD 208000
Additional compensation / rewards: Ivalua also offers exceptional benefits including medical, dental, vision and transportation.
#LI-SG1
#LI-HYBRID
#LI-
DNI
About Ivalua
Sourced by ZipRecruiter
Industry
Software development
Company size
51 - 200 Employees
Headquarters location
Redwood City, CA, US
Year founded
2000